Qatar's Qatar Central Bank (QCB) Technology Risks Regulation sets one of the Gulf's most specific penetration testing mandates for banks: semi-annual vulnerability assessment and penetration testing of infrastructure and network devices (section 9.1.1.5), plus two penetration testing exercises and two vulnerability assessments per year on applications (section 9.4.3), following OWASP, OSSTMM and SANS. For government, the National Information Assurance (NIA) Policy v2.0 requires an annual Security Assurance Plan that may include penetration testing (control IM 9) and independent pre-production testing (control SS 7). The QCB rules apply to all licensed banks (with parallel regulations for payment providers and insurers); the NIA Policy applies to government agencies. The National Cyber Security Agency (NCSA) oversees the national layer.
// 01 Who regulates cybersecurity in Qatar?
Two bodies matter for penetration testing. The Qatar Central Bank (QCB) regulates the financial sector — banks, payment service providers and insurers — and its cybersecurity rules are the most prescriptive in the country. The National Cyber Security Agency (NCSA), established in 2021, owns the national cybersecurity architecture: it holds the National Information Assurance Policy (previously issued by the Ministry of Transport and Communications and Q-CERT), classifies critical sectors, and publishes national data-classification and cloud-security policies. Which regime governs you depends on whether you are a financial institution, a government agency, or a critical-sector operator — and some organisations answer to more than one.
// 02 QCB penetration testing requirements for banks
The QCB Technology Risks Regulation is refreshingly explicit where many frameworks are vague — it fixes the frequency. Two sections carry the core testing mandate, and both require testing twice a year.
Section 9.1.1.5 (infrastructure & network): "Vulnerability assessment and penetration testing of infrastructure and network devices must be performed on a semi-annual basis as specified in the vulnerability assessment and penetration testing guidelines."
Section 9.4.3 (applications): a comprehensive vulnerability assessment using automated tools and manual techniques "at a minimum of two … on an annual basis" following OWASP/OSSTMM/SANS, and "The bank shall conduct two penetration testing exercises, or more frequently as needed, on an annual basis." Business-risk acceptance for open vulnerabilities is reviewed semi-annually.
Section 9.4.2 (application lifecycle): application security testing of web and mobile applications throughout the lifecycle — pre-implementation, post-implementation, and after major changes.
Read together, a Qatari bank must run semi-annual VAPT on its infrastructure and network, and two penetration tests plus two vulnerability assessments a year on its applications — with additional testing around every major application change. That is a materially heavier cadence than the annual testing many frameworks expect, and it should anchor any Qatari bank's testing calendar.
// 03 The NIA Policy for government
Outside the financial sector, the National Information Assurance (NIA) Policy v2.0 is Qatar's baseline. It is structured into governance-and-process controls and technical security controls across domains such as network, software, access and monitoring. Unlike the QCB rules, it does not carry a single "test every N months" control — instead, penetration testing is embedded within the assurance and software-security controls.
Annual Security Assurance Plan
"The Incident Management coordinator is responsible for developing and executing an annual Security Assurance Plan. This may include activities such as penetration testing, audit of security procedures, and incident scenario testing." Penetration testing is named as an activity within a mandatory annual plan.
Independent pre-production testing
"Software should be reviewed and/or tested for vulnerabilities before it is used in a production environment. Software SHOULD be reviewed and/or tested by an independent party and not by the developer." Independence is explicit.
So a Qatari government agency evidences the NIA Policy through an annual assurance plan that includes penetration testing, plus independent security testing of software before it goes live. The "independent party, not the developer" wording in SS 7 is worth noting — it rules out self-testing by the build team.
// 04 Who must comply
| Framework | Applies to | Testing cadence |
|---|---|---|
| QCB Technology Risks | Licensed banks | Semi-annual VAPT + 2 pen tests/yr (apps) |
| QCB PSP Regulation (2022) | Payment service providers | Sector cyber controls |
| QCB Insurance Regulation | Insurers | Sector cyber controls |
| NIA Policy v2.0 | Government agencies | Annual assurance plan (IM 9) |
| NCSA critical-sector standards | Critical national infrastructure | Periodic assessments |
// 05 The NCSA national layer
Above the sector regulators, the National Cyber Security Agency develops Qatar's national cyber framework, classifies critical sectors, and issues cross-cutting policies — including a National Data Classification Policy (C0–C4 tiers) and a Cloud Security Policy. Critical-infrastructure operators are subject to periodic security assessments under this national layer. The detailed control text of the national framework is not fully public, so we describe the requirement functionally: critical-sector operators should expect to evidence periodic penetration testing and assessment, in addition to any sector-specific rules such as the QCB regulation. For a bank that is also designated critical infrastructure, that means satisfying both the QCB cadence and the NCSA assessment expectations — efficiently done by scoping one testing programme against both.
// 06 Frequently asked questions
Does Qatar require penetration testing for banks?
Yes. QCB requires semi-annual VAPT of infrastructure and network devices, and two penetration tests plus two vulnerability assessments a year on applications.
How often must banks test?
Twice a year — semi-annual infrastructure VAPT and two application penetration tests annually, following OWASP/OSSTMM/SANS, plus testing around major changes.
What does the NIA Policy require?
No single fixed frequency, but IM 9 requires an annual Security Assurance Plan that may include penetration testing, and SS 7 requires independent pre-production testing.
Who regulates it?
QCB for the financial sector; NCSA for the national framework, critical sectors and the NIA Policy.
// 07 Sources
- Qatar Central Bank, Technology Risks Regulation (January 2018) — sections 9.1.1.5, 9.4.2 and 9.4.3 (quoted). Parallel QCB regulations for Payment Service Providers (2022) and the Insurance Sector.
- Qatar National Information Assurance (NIA) Policy v2.0 — controls IM 9 and SS 7 (quoted); issued under the National Cyber Security Agency.
- NCSA National Data Classification Policy and Cloud Security Policy.
Control references reflect the QCB Technology Risks Regulation and NIA Policy v2.0 as published. Confirm the current text for your institution before relying on this for a regulatory submission.